WordPress.org has released WordPress 3.0.4 to address a vulnerability in the HTML sanitation library. Exploitation of this vulnerability may allow an attacker to insert arbitrary HTML and script code into the browser session.
US-CERT encourages users and administrators to review the WordPress.org blog entry and apply any necessary updates to help mitigate the risks.